Robustness evaluation for deep neural networks via mutation decision boundaries analysis

被引:5
|
作者
Lin, Renhao [1 ]
Zhou, Qinglei [1 ]
Wu, Bin [1 ]
Nan, Xiaofei [1 ]
机构
[1] Zhengzhou Univ, Sch Comp & Artificial Intelligence, Zhengzhou 450001, Peoples R China
基金
中国国家自然科学基金;
关键词
Neural networks; Robustness verification; Mutation testing; Decision boundary; Unstable points; Adversarial examples;
D O I
10.1016/j.ins.2022.04.020
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
While recent years have witnessed the power of deep neural networks in representation learning, it is well known that their robustness is a congenital defect. Formal verification sheds some light to tackle this issue, which achieves it by a rigorous mathematical reasoning. Nevertheless, such technique still suffers from the efficiency and scalability problems. In light of this, we develop a novel solution to make a pre-analysis before performing verification. Specifically, we argue that the points near the actual decision boundary of the neural network are more likely to not satisfy robustness. As such, we focus on locating unstable points in the input set, instead of point-by-point verification. Borrowing from mutation testing, we adopt the analysis of the mutation decision boundaries to evaluate the local robustness of the inputs. Also, we design a robustness metric to guide the selection of unstable points. Then, the effective adversarial examples can be generated by perturbing these unstable points. We conduct extensive experiments on two neural network verification benchmarks, demonstrating the rationality, effectiveness and efficiency improvement of our solution. (C) 2022 Elsevier Inc. All rights reserved.
引用
收藏
页码:147 / 161
页数:15
相关论文
共 50 条
  • [1] Decision Boundaries of Deep Neural Networks
    Karimi, Hamid
    Derr, Tyler
    [J]. 2022 21ST IEEE INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND APPLICATIONS, ICMLA, 2022, : 1085 - 1092
  • [2] Towards Robustness of Deep Neural Networks via Regularization
    Li, Yao
    Min, Martin Renqiang
    Lee, Thomas
    Yu, Wenchao
    Kruus, Erik
    Wang, Wei
    Hsieh, Cho-Jui
    [J]. 2021 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2021), 2021, : 7476 - 7485
  • [3] Prioritizing Test Inputs for Deep Neural Networks via Mutation Analysis
    Wang, Zan
    You, Hanmo
    Chen, Junjie
    Zhang, Yingyi
    Dong, Xuyuan
    Zhang, Wenbin
    [J]. 2021 IEEE/ACM 43RD INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING (ICSE 2021), 2021, : 397 - 409
  • [4] Robustness evaluation of deep neural networks for endoscopic image analysis: Insights and strategies
    Jaspers, Tim J. M.
    Boers, Tim G. W.
    Kusters, Carolus H. J.
    Jong, Martijn R.
    Jukema, Jelmer B.
    Groof, Albert J. de
    Bergman, Jacques J.
    With, Peter H. N. de
    Sommen, Fons van der
    [J]. MEDICAL IMAGE ANALYSIS, 2024, 94
  • [5] Feature Extraction for Deep Neural Networks Based on Decision Boundaries
    Woo, Seongyoun
    Lee, Chulhee
    [J]. PATTERN RECOGNITION AND TRACKING XXVIII, 2017, 10203
  • [6] Improving the Robustness of Deep Neural Networks via Stability Training
    Zheng, Stephan
    Song, Yang
    Leung, Thomas
    Goodfellow, Ian
    [J]. 2016 IEEE CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2016, : 4480 - 4488
  • [7] Scalable and Modular Robustness Analysis of Deep Neural Networks
    Zhong, Yuyi
    Ta, Quang-Trung
    Luo, Tianzuo
    Zhang, Fanlong
    Khoo, Siau-Cheng
    [J]. PROGRAMMING LANGUAGES AND SYSTEMS, APLAS 2021, 2021, 13008 : 3 - 22
  • [8] Improving Adversarial Robustness of Deep Neural Networks via Linear Programming
    Tang, Xiaochao
    Yang, Zhengfeng
    Fu, Xuanming
    Wang, Jianlin
    Zeng, Zhenbing
    [J]. THEORETICAL ASPECTS OF SOFTWARE ENGINEERING, TASE 2022, 2022, 13299 : 326 - 343
  • [9] Enhancing Robustness Verification for Deep Neural Networks via Symbolic Propagation
    Yang, Pengfei
    Li, Jianlin
    Liu, Jiangchao
    Huang, Cheng-Chao
    Li, Renjue
    Chen, Liqian
    Huang, Xiaowei
    Zhang, Lijun
    [J]. FORMAL ASPECTS OF COMPUTING, 2021, 33 (03) : 407 - 435
  • [10] Robustness Verification of Classification Deep Neural Networks via Linear Programming
    Lin, Wang
    Yang, Zhengfeng
    Chen, Xin
    Zhao, Qingye
    Li, Xiangkun
    Liu, Zhiming
    He, Jifeng
    [J]. 2019 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR 2019), 2019, : 11410 - 11419